AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2025-31114

CRITICAL · CVSS 9.3 EPSS 0.88% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

Fooocus image generating software versions 2.5.5 and earlier are critically vulnerable to remote code execution due to the insecure handling of metadata JSON via the eval function in the web UI. This flaw allows an attacker with access to the web interface to execute arbitrary code on the affected instance. Organizations using Fooocus should prioritize addressing this vulnerability, as no patched versions are currently available, and immediate mitigation measures are recommended.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2025-31114
Severity
CRITICAL
CVSS
9.3
EPSS
0.88%

Original NVD Description

Fooocus is an image generating software. In versions 2.5.5 and prior, the Fooocus web UI is vulnerable to remote code execution due to the unsafe use of eval when processing metadata JSON. An attacker with access to the Fooocus web UI may be able to execute arbitrary code on the instance. As of time of publication, no known patched versions are available, but a suggested fix pull request is available.